ClickFix relies on tricking users into essentially hacking themselves by running commands that compromise their computers. In ...
Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code ...
The Bitwarden CLI NPM package compromise is tied to a Checkmarx supply chain attack and references the Shai-Hulud worm.
A North Korean APT has crafted malicious software packages to appeal to AI coding agents, while ‘slopsquatting’ shows the ...
Four SAP NPM packages compromised in the Mini Shai-Hulud supply chain attack trigger a Bun runtime to install an information ...
Malicious Lightning 2.6.2/2.6.3 released April 30 enable credential theft via hidden payload, leading to PyPI quarantine and ...
Nineteen extra charges have been laid against a 24-year-old man accused of carrying out a deadly mass shooting on a Jewish festival in 2025. The attack took place at the iconic Bondi Beach in Sydney.
Four npm packages linked to SAP's Cloud Application Programming Model were hijacked. The hackers added code that steals ...
The Tumbler Ridge, B.C., high school where six people were killed in one of Canada’s worst mass shootings will be torn down ...
VS Code extensions since Dec 21, 2025 fuel GlassWorm v2, installing cross-IDE malware and stealing credentials.